Doesn the SSH specification include the possibiliy of OpenPGP certificates on the wire?
It does, but the free implementations don’t seem to support it. The Monkeysphere approach is to handle the verification out-of-band, instead of forcing a change on the wire. This makes things easier to deploy and has been helpful because it lets us concentrate on the bigger questions of trust and verification, instead of getting mired in patching source and wire protocol issues.